Skip to content
LogoLogScale DocumentationLibraryGuidance Release Notes Integrations Query Examples Training APIGraphQLSearch Archives Contact Support
🔖 🔔 ੆Help button for documentation
    • Data Analysis Overview
    • LogScale Web Interface
      • System Tabs and Falcon Icon
      • Navigation Icons
        • Notifications
        • Releases and Release Notes
        • Help
        • Avatar icon
      • Informational Panels
      • Left-hand Navigation Panel
      • Table Components
      • Repositories and Views
        • Repositories and Views Menubar
        • Search Interface
        • Dashboards Interface
        • Automation Interface
        • Parsers Interface
        • Resources Interface
          • Asset Type Interface Elements
        • Settings Interface
      • All Dashboards
      • Data Ingest
    • Manage Repositories and Views
      • Create Repository or View
      • Repository and View Settings
      • Delete a Repository or View
      • Falcon LTR Repositories
      • Lookup Files
        • Supported File Types and Formats
        • Create a Lookup File
        • Manage Lookup Files
        • Lookup Files Operations with match()
    • Manage Your LogScale Account
    • Parse Data
      • Built-in Parsers
      • Custom Parsers
        • Create a Parser
        • Write a Parser
          • Example: Parsing Log Lines
          • Example: Parsing JSON
          • Parsers Validation Errors
          • Normalize and Validate Against CPS Schema
      • Manage Parsers
      • Ingest Tokens
      • Parser Errors
      • Removing Fields
      • Parsing Event Tags
      • Parsing Timestamps
    • Search Data
      • Query Editor
      • Event Fields
      • Display Fields
      • Manage Fields
      • Display Results and Events
      • Inspect Events
      • Copy Rows
      • Look Up Events
      • Show in Context
      • Format Columns
      • Column Properties
      • Field Data Types
      • Field Interactions
      • Choose Visualization
      • Highlight Filter Match
      • Change Time Interval
      • Set Time Zone
      • Save Results
      • Export Data
      • Search Status
      • Event List Interactions
      • Field Aliasing
        • Configuring Field Aliasing
        • Managing Field Aliasing
        • Searching with Field Aliasing
        • Understanding Field Mapping Requirements
        • Understanding Schema Requirements
    • Write Queries
      • Basic Query Principles
      • Returned Events
      • Query Management
        • Write a New Query
        • Save Searches
          • Create a Saved Search
          • Manage Saved Searches
          • Grant Permissions for Saved Queries
        • Use Saved Queries in Interactions
      • Common Queries
      • Statement Order for Better Queries
      • Query Readability and Better Usage
    • Query Language Syntax
      • Comments
      • Query Filters
      • Operators
      • Adding Fields to Events
      • User Parameters/Variables
      • Conditional Evaluation
      • Array Syntax
      • Expressions
      • Saved Searches (User Functions)
      • Function Syntax
      • Time Syntax
        • Supported Time Zones
        • Relative Time Syntax
      • Referencing Resources
      • Regular Expression Syntax
        • Regular Expression Engine V2 Syntax Patterns
        • Regular Expression Syntax Patterns
          • Unsupported Regular Expression Patterns
        • Regular Expression Flags
        • LogScale Regular Expression Engines
        • Differences from Other Regex Implementations
      • Persisted Aggregations Syntax
    • Query Joins and Lookups
      • Types of Join
      • Join Methods
      • Asset Resolution in Subqueries
      • Using Ad-hoc Tables
      • Using Lookup Files
        • Using the readFile() Function
        • Using the match() Function
      • Using join() or selfJoin()
        • Using the join() Function
        • Using the selfJoin() Function
        • Join Operation and Optimization
    • Query Functions
      • Aggregate Query Functions
      • Array Query Functions
      • Comparison Query Functions
      • Conditional Query Functions
      • Data Manipulation Query Functions
      • Event Information Query Functions
      • Filtering Query Functions
      • Formatting Query Functions
      • Geolocation Query Functions
      • Hash Query Functions
      • Join Query Functions
      • Query Debugging Functions
      • Math Query Functions
      • Network and Location Query Functions
      • Parsing Query Functions
      • Preamble Query Functions
      • Regular Expression Query Functions
      • Security Related Query Functions
      • Sequence Query Functions
      • Statistics Query Functions
      • String Query Functions
      • Time and Date Query Functions
      • Transformation Query Functions
      • Widget Query Functions
      • accumulate()
      • array:append()
      • array:contains()
      • array:dedup()
      • array:drop()
      • array:eval()
      • array:exists()
      • array:filter()
      • array:intersection()
      • array:length()
      • array:reduceAll()
      • array:reduceColumn()
      • array:reduceRow()
      • array:regex()
      • array:rename()
      • array:sort()
      • array:union()
      • asn()
      • avg()
      • base64Decode()
      • base64Encode()
      • beta:param()
      • beta:repeating()
      • bitfield:extractFlags()
      • bitfield:extractFlagsAsArray()
      • bitfield:extractFlagsAsString()
      • bucket()
      • callFunction()
      • cidr()
      • coalesce()
      • collect()
      • communityId()
      • concat()
      • concatArray()
      • copyEvent()
      • correlate()
      • count()
      • counterAsRate()
      • createEvents()
      • crypto:md5()
      • crypto:sha1()
      • crypto:sha256()
      • default()
      • defineTable()
      • drop()
      • dropEvent()
      • duration()
      • end()
      • eval()
      • eventFieldCount()
      • eventInternals()
      • eventSize()
      • explain:asTable()
      • fieldset()
      • fieldstats()
      • findTimestamp()
      • format()
      • formatDuration()
      • formatTime()
      • geography:distance()
      • geohash()
      • getField()
      • groupBy()
      • hash()
      • hashMatch()
      • hashRewrite()
      • head()
      • if()
      • in()
      • ioc:lookup()
      • ipLocation()
      • join()
      • json:prettyPrint()
      • kvParse()
      • length()
      • linReg()
      • lower()
      • lowercase()
      • match()
      • matchAsArray()
      • math:abs()
      • math:arccos()
      • math:arcsin()
      • math:arctan()
      • math:arctan2()
      • math:ceil()
      • math:cos()
      • math:cosh()
      • math:deg2rad()
      • math:exp()
      • math:expm1()
      • math:floor()
      • math:log()
      • math:log10()
      • math:log1p()
      • math:log2()
      • math:mod()
      • math:pow()
      • math:rad2deg()
      • math:sin()
      • math:sinh()
      • math:spherical2cartesian()
      • math:sqrt()
      • math:tan()
      • math:tanh()
      • max()
      • min()
      • neighbor()
      • now()
      • objectArray:eval()
      • objectArray:exists()
      • parseCEF()
      • parseCsv()
      • parseFixedWidth()
      • parseHexString()
      • parseInt()
      • parseJson()
      • parseLEEF()
      • parseTimestamp()
      • parseUri()
      • parseUrl()
      • parseXml()
      • partition()
      • percentage()
      • percentile()
      • range()
      • rdns()
      • readFile()
      • regex()
      • rename()
      • replace()
      • reverseDns()
      • round()
      • sample()
      • sankey()
      • select()
      • selectFromMax()
      • selectFromMin()
      • selectLast()
      • selfJoin()
      • selfJoinFilter()
      • series()
      • session()
      • setField()
      • setTimeInterval()
      • shannonEntropy()
      • slidingTimeWindow()
      • slidingWindow()
      • sort()
      • split()
      • splitString()
      • start()
      • stats()
      • stdDev()
      • stripAnsiCodes()
      • subnet()
      • sum()
      • table()
      • tail()
      • test()
      • text:contains()
      • text:editDistance()
      • text:editDistanceAsArray()
      • text:endsWith()
      • text:length()
      • text:positionOf()
      • text:startsWith()
      • text:substring()
      • time:dayOfMonth()
      • time:dayOfWeek()
      • time:dayOfWeekName()
      • time:dayOfYear()
      • time:hour()
      • time:millisecond()
      • time:minute()
      • time:month()
      • time:monthName()
      • time:second()
      • time:weekOfYear()
      • time:year()
      • timeChart()
      • tokenHash()
      • top()
      • transpose()
      • unit:convert()
      • upper()
      • urlDecode()
      • urlEncode()
      • wildcard()
      • window()
      • worldMap()
      • writeJson()
      • xml:prettyPrint()
    • Dashboards
      • Step-by-Step Guide to Dashboards
      • Create Dashboards
      • Manage Dashboards
      • Customize Dashboards
      • Design the Dashboard Layout
        • Dashboard Sections
      • Work with Time on Dashboards
        • Shared Time Selector
        • Widget Time Selector
        • Section Time Selector
        • Live Dashboards
        • Time Zone Settings
        • Default Time Settings for Dashboards
      • Make your Dashboard Interactive
        • Apply Dashboard Filters
        • Work with Dashboard Parameters
        • Work with Dashboard Interactions
      • Share Dashboards
        • Disabling Access to Shared Dashboards
        • Restricting Access with IP Filters
      • Export Dashboards as PDF
        • PDF Export Options
    • Automation
      • Triggers
        • What Trigger Type to Choose
        • General Information About Triggers
        • Trigger Management
          • Create Triggers
          • Edit Triggers
          • Manage Triggers
        • Trigger Properties
          • General Properties
          • Configuration Properties
          • Actions Properties
          • Advanced Settings
          • Scheduled Search Properties
        • Monitor, Diagnose, and Troubleshoot Triggers
          • Monitor Triggers with humio-activity Repository
          • Aggregate Alert Errors and Solutions
          • Scheduled Search Errors and Solutions
          • Filter Alert Errors and Solutions
          • Legacy Alert Errors and Solutions
          • Errors when Using Live join() Functions
      • Actions
        • Create Actions
        • Manage Actions
        • Action Type: Email
        • Action Type: Falcon LogScale Repository
        • Action Type: OpsGenie
        • Action Type: PagerDuty
        • Action Type: S3
        • Action Type: Slack
        • Action Type: Lookup File
        • Action Type: VictorOps (Splunk On-Call)
        • Action Type: Webhooks
        • Send aggregate results to actions
        • Message Templates and Variables
      • Schedule PDF Reports
        • Scheduled Reports Security
          • Create a Scheduled PDF Role using the web interface
        • Managing Scheduled Reports
        • Create Scheduled Reports
        • Edit Scheduled Reports
        • Scheduled Report Operation and Limitations
        • Scheduled Report Errors and Resolutions
      • Cron Scheduling
    • Template Language
      • Template Expressions
      • Template Variable Types
      • Template Examples
    • Keyboard Shortcuts
Falcon LogScale Documentation
/ Data Analysis 1.220.0-1.228.3
/ Search Data
/ Field Aliasing
Content was updated:Aug 8, 2026

Searching with Field Aliasing

Field aliasing affects search behavior in the following ways:

  • The aliased fields will exist on an event at search time, whenever the tag conditions are met on the same event.

  • The aliased fields contain the exact same data as the original field, and they behave identically to other fields when operating on them in the query language.

  • If an event contains a field with the same name as an alias, then the alias will overshadow the existing field.

  • Keep original field? option (see Figure 122, “Match fields and aliases”):

    • If disabled, only the alias can be searched. The original field is no longer searchable.

    • If enabled, the original field will still be searchable. Both the source field and alias can be used independently in queries — operations like renaming or reassigning one field will not affect the other. This means that existing queries that use the original/source field names will still continue to work. This behavior can, however, come at the cost of some performance.

flowchart LR classDef behavior fill:#E6F3FF,stroke:#0066CC,stroke-width:2px A1[Tag conditions met on event] -->|Creates| A2[Aliased fields exist at search time] B1[Original fields] -->|Same data & behavior| B2[Aliased fields] C1[Original and alias have same name] -->|Results in| C2[Alias overshadows existing field] D1[Keep Original Field Option] --> D2{Enabled?} D2 -->|No| D3[Only alias searchable Original field not searchable] D2 -->|Yes| D4[Both fields searchable Can be used independently Original queries work May impact performance] class A1,A2,B1,B2,C1,C2 behavior class D1,D2,D3,D4 option
flowchart LR classDef behavior fill:#E6F3FF,stroke:#0066CC,stroke-width:2px A1[Tag conditions met on event] -->|Creates| A2[Aliased fields exist at search time] B1[Original fields] -->|Same data & behavior| B2[Aliased fields] C1[Original and alias have same name] -->|Results in| C2[Alias overshadows existing field] D1[Keep Original Field Option] --> D2{Enabled?} D2 -->|No| D3[Only alias searchable Original field not searchable] D2 -->|Yes| D4[Both fields searchable Can be used independently Original queries work May impact performance] class A1,A2,B1,B2,C1,C2 behavior class D1,D2,D3,D4 option

Figure 129. Field Aliasing Search


Searches with Live Queries

Whenever you activate a schema or make changes to an existing active schema, these changes will take effect immediately, meaning any new search will use the new configuration.

For existing running live queries (such as alerts, or an already opened dashboard), these queries need to be restarted in order for the new configuration to take effect.

An exception to this rule is if the query contains a join(), selfJoin() or selfJoinFilter() function: these will use the new configuration on their next refresh. See Searches with Join Queries for more details.

Searches with Join Queries

As described in Join Operation and Optimization, queries with join functions simulate liveness by executing in repeated intervals. For queries with join functions where field aliasing is enabled (that is, there is an active schema on the view where the query is executed), the latest configuration of schema and alias mappings are used on each repeated execution.

Unlike live queries without joins (changes in the configuration does not impact an already running query) live queries using joins must be restarted at each schema or alias mappings configuration change.

As Join Query Functions allow specifying the repository for which the subquery should execute, the subquery will use the field alias configuration of the specified repository.

Searches in a Multi-Cluster Setup

Field aliasing can be used with LogScale Multi-Cluster Search. Only the schema active on the local cluster (either organization level or applied on the Multi-Cluster view) will be effective and applied to data from all remote views connected in the multi-cluster view. You can still use field aliasing on the remote clusters, however it will be effective only when searching the remote cluster directly. When running the search from the multi cluster view, schemas active on remote clusters will be ignored.

If you want to apply different mappings for each remote cluster, Multi-Cluster Views allow setting up an additional tag (#clusteridentity which is set to the value Cluster identity tag when configuring a connection) that can be used in the tag conditions of alias mappings.

For more information, see LogScale Multi-Cluster Search documentation.

Searches with Query Prefixes

LogScale has several types of query prefixes that are implicitly added to any query; field aliasing cannot always be used with these query prefixes. This means that those filters will not work with aliased fields, which are disabled for those queries. Query prefixes are:

Query Prefix Field Aliasing
View Connection filters, explained at Views Filtering Disabled. Aliased fields cannot be accessed in the view connection filter.
Deletion prefixes in Redact Events API Disabled. Aliased fields are not available in a filter query used with this API (it only operates on the parsed fields). If the same query is run on the Search page (for example, to check which events to delete before running the API) where field aliasing is set up, the search will produce different results. To avoid such a discrepancy, you may either disable the field aliasing configuration when running the query on search, or ensure you are not using aliased fields in the filter query executed through the API.
Role/User query prefix, explained at Assign Roles to Groups Enabled. You can access aliased fields when you define a query prefix for the role/user filter query.
Support
  • Twitter
  • LinkedIn
  • Youtube

© 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

Sections on this Page

Searches with Live Queries
Searches with Join Queries
Searches in a Multi-Cluster Setup
Searches with Query Prefixes
  • Other articles on this topic

    • humio-audit Event types
    • humio-audit Query Structure
    • API token security policies (Cloud)
    • API token security policies (Self-Hosted)
    • Action Type: Webhooks
    • Actions Properties
    • Actions security policies (Cloud)
    • Actions security policies (Self-Hosted)
    • Actor Structure
    • Add Temporary Events and URLs
    • Add a local connection (Self-Hosted)
    • Add a remote connection (Self-Hosted)
    • Advanced Multi-Cluster Topics (Self-Hosted)
    • Advanced Settings
    • Aggregate Alert Errors and Solutions
    • Alert Type Proportion in Detection Sources
    • Alert, Scheduled Search, and Scheduled Report Errors and Resolutions
    • Alerts and Saved Searches Best Practices
    • Apply Dashboard Filters
    • Assign Roles to Groups (Cloud)
    • Assign Roles to Groups (Self-Hosted)
    • Audit Logging (Cloud)
    • Audit Logging (Self-Hosted)
    • Authentication Methods Distribution
    • Automation
    • Automations
    • Auxiliary Nodes (Self-Hosted)
    • Azure Reference Architecture
    • Bar Chart Examples Gallery
    • Bar Chart Property Reference
    • Bar Chart Usage and Data Format
    • Bar Chart Widget
    • Basic Configuration
    • Behavior when changing token security policies (Cloud)
    • Behavior when changing token security policies (Self-Hosted)
    • Bucket Storage Dashboard
    • Building Dashboards, Widgets, Charts, and Graphs
    • Change Remote connections (Self-Hosted)
    • Change local connections (Self-Hosted)
    • Charting Commits in GitHub
    • Charting Log Levels
    • Charting Metric Data
    • Cluster Management (Self-Hosted)
    • Cluster Nodes (Self-Hosted)
    • Cluster Statistics (Cloud)
    • Cluster Statistics (Self-Hosted)
    • Common Structures
    • Configuration Properties
    • Configuration Variables (Self-Hosted)
    • Configure Multi-Cluster (Self-Hosted)
    • Configure Security (Cloud)
    • Configure Security (Self-Hosted)
    • Configure session cookies (Self-Hosted)
    • Connect: Passthru, Pipeline, or Pack
    • Create Dashboards
    • Create Persisted Aggregations
    • Create Triggers
    • Create Widgets
    • Create a Multi-Cluster View using GraphQL (Self-Hosted)
    • Create a Scheduled PDF Role using the web interface
    • Create an IP Filter (Cloud)
    • Create an IP Filter (Self-Hosted)
    • Create and Manage Multi-Cluster Views using LogScale UI (Self-Hosted)
    • Cron Scheduling
    • Customize Dashboards
    • Dashboard Best Practices
    • Dashboard Sections
    • Dashboard Widgets
    • Dashboard security policies (Cloud)
    • Dashboard security policies (Self-Hosted)
    • Dashboards
    • Data Ingestion Overview
    • Data Retention (Cloud)
    • Data Retention (Self-Hosted)
    • Data Visualization
    • Datasources
    • Default Time Settings for Dashboards
    • Delay run
    • Delete a Repository or View
    • Delete connections (Self-Hosted)
    • Design the Dashboard Layout
    • Detection Counts with Severity Average
    • Digest Rules
    • Disabling Access to Shared Dashboards
    • Display Different Statuses
    • Display Number of Errors
    • Display Query Memory
    • Display Small Multiple Charts
    • Displaying Number of Errors
    • Displaying Statistics from a Build
    • Displaying Values in a Grid
    • Displaying a Non-Numeric Value
    • Displaying a Trend with a Timechart
    • Distribution of Security Alert Severities
    • Dynamic Configuration Parameters (Cloud)
    • Dynamic Configuration Parameters (Self-Hosted)
    • Edit Persisted Aggregations
    • Edit Triggers
    • Edit an IP Filter (Cloud)
    • Edit an IP Filter (Self-Hosted)
    • Enable Multi-Cluster Feature Flags (Self-Hosted)
    • Enable single user authentication
    • Errors when Using Live join() Functions
    • Event Detection Across Severity Levels
    • Event Forwarders
    • Event Forwarding
    • Event List Property Reference
    • Event List Usage and Data Format
    • Event List Widget
    • Examples of queries for humio-audit
    • Export Dashboards as PDF
    • Failed and Successful Authentication Attempts
    • Filter Alert Errors and Solutions
    • Filter Match Highlighting
    • Gauge Examples Gallery
    • Gauge Property Reference
    • Gauge Usage and Data Format
    • Gauge Widget
    • General Information About Triggers
    • General Properties
    • Geohash Performance Clustering
    • Get Dynamic Configuration List (Cloud)
    • Get Dynamic Configuration List (Self-Hosted)
    • Github Push Events
    • Grammar Subset
    • Grant Permissions to Specific Assets (Cloud)
    • Grant Permissions to Specific Assets (Self-Hosted)
    • Group Memberships (Cloud)
    • Group Memberships (Self-Hosted)
    • Group Synchronization (Cloud)
    • Group Synchronization (Self-Hosted)
    • Guidelines for Submitting a Package to LogScale Marketplace
    • Health Checks (Self-Hosted)
    • Heat Map Examples Gallery
    • Heat Map Property Reference
    • Heat Map Usage and Data Format
    • Heat Map Widget
    • Hint: Deselect Series in Widgets
    • Hint: Embedding iFrame Widgets
    • How-To: Deploy AWS Reference Architecture
    • How-To: Install Kubernetes Reference Architecture
    • IP Filter
    • IP Filter Rules (Cloud)
    • IP Filter Rules (Self-Hosted)
    • IP Filters (Cloud)
    • IP Filters (Self-Hosted)
    • IP-Based Geographic Distribution
    • Identify Queries on Remote Clusters (Self-Hosted)
    • Ingest Listeners
    • Ingest Usage Management (Cloud)
    • Ingest delay handling for aggregate alerts
    • Ingest delay handling for legacy alerts
    • Ingestion: Storage Phase
    • Insights Errors Dashboard
    • Insights Hosts Dashboard
    • Insights Ingest Dashboard
    • Insights Overview Dashboard
    • Insights Request-Response Dashboard
    • Insights Search Dashboard
    • Insights Segments & Datasources Dashboard
    • Install Falcon LogScale Collector on Linux - Custom
    • Instance Administration (Cloud)
    • Instance Administration (Self-Hosted)
    • Instance Sizing
    • JVM Configuration
    • Kafka Cluster (Self-Hosted)
    • Kafka Configuration
    • Kafka Dashboard
    • Legacy Alert Errors and Solutions
    • License Installation
    • Limitation: Widgets with Live join() Functions
    • Limits and Standards (Cloud)
    • Limits and Standards (Self-Hosted)
    • Live Dashboards
    • Live Search Request
    • Log LogScale to LogScale (Self-Hosted)
    • LogScale Internal Logging (Cloud)
    • LogScale Internal Logging (Self-Hosted)
    • LogScale Measurement Repositories (Cloud)
    • LogScale Measurement Repositories (Self-Hosted)
    • LogScale Multi-Cluster Search (Self-Hosted)
    • LogScale Overview
    • LogScale SaaS Upgrades (Cloud)
    • LogScale System Repository Schema Guide
    • LogScale URLs and Endpoints (Cloud)
    • LogScale URLs and Endpoints (Self-Hosted)
    • LogScale on Bare Metal - Installation Preparation
    • Make your Dashboard Interactive
    • Malware Types by Infection Count (In Small Multiples)
    • Manage Dashboards
    • Manage Groups (Cloud)
    • Manage Groups (Self-Hosted)
    • Manage IP Filters (Cloud)
    • Manage IP Filters (Self-Hosted)
    • Manage Persisted Aggregations
    • Manage Roles (Cloud)
    • Manage Roles (Self-Hosted)
    • Manage Triggers
    • Manage User Roles (Cloud)
    • Manage User Roles (Self-Hosted)
    • Manage Users (Cloud)
    • Manage Users (Self-Hosted)
    • Manage Users and Permissions (Cloud)
    • Manage Users and Permissions (Self-Hosted)
    • Manage Widgets
    • Managing Falcon LTR Repositories
    • MaxMind Configuration
    • Measure Data Ingest (Cloud)
    • Measure Data Ingest (Self-Hosted)
    • Measure and Manage Ingest Usage (Self-Hosted)
    • Message Templates and Variables
    • Messages During Multi-Cluster Queries (Self-Hosted)
    • Monitor Trigger Execution through the humio-activity Repository
    • Monitor Usage (Cloud)
    • Monitor Usage (Self-Hosted)
    • Monitor, Diagnose, and Troubleshoot Triggers
    • Multi-Cluster Security (Self-Hosted)
    • Naming and Informational Notes
    • Network Traffic
    • Network Traffic by Protocol
    • Node Identifiers (Self-Hosted)
    • Node-Level Metrics
    • Note Widget
    • Note Widget Property Reference
    • Notifications
    • Object-Level Metrics
    • Optimize Ingestion (Cloud)
    • Optimize Ingestion (Self-Hosted)
    • Organization API tokens security policies (Cloud)
    • Organization API tokens security policies (Self-Hosted)
    • PDF Export Options
    • Parameter Panel Widget
    • Permissions Requirements (Cloud)
    • Permissions Requirements (Self-Hosted)
    • Persisted Aggregation Management
    • Persisted Aggregations
    • Personal API token security policy (Cloud)
    • Personal API token security policy (Self-Hosted)
    • Pie Chart Examples Gallery
    • Pie Chart Property Reference
    • Pie Chart Usage and Data Format
    • Pie Chart Widget
    • Queries and Querying
    • Query Actor Data
    • Query Basics
    • Query Debugging Functions
    • Query Function Limitations (Self-Hosted)
    • Query Operation
    • Query Readability and Format
    • Query data in the humio Repository
    • Reference Material (Cloud)
    • Reference Material (Self-Hosted)
    • Replacing Hardware in a Cluster
    • Repository and View API tokens security policy (Cloud)
    • Repository and View API tokens security policy (Self-Hosted)
    • Repository and View Permissions (Cloud)
    • Repository and View Permissions (Self-Hosted)
    • Repository and View Settings
    • Response Time
    • Restricting Access with IP Filters
    • Retry for aggregate alerts
    • Sankey Diagram Widget
    • Sankey Examples Gallery
    • Sankey Property Reference
    • Sankey Usage and Data Format
    • Scatter Chart Property Reference
    • Scatter Chart Widget
    • Scheduled Report Operation and Limitations
    • Scheduled Reports Security
    • Scheduled Search Errors and Solutions
    • Searching with Field Aliasing
    • Section Time Selector
    • Security policies (Cloud)
    • Security policies (Self-Hosted)
    • Security, Logins, and Access Control
    • Send Events That Produced Aggregate Results to Actions
    • Service Performance Monitoring
    • Session management (Cloud)
    • Session management (Self-Hosted)
    • Set Up Roles in a File (Self-Hosted)
    • Set a Dynamic Configuration Value (Cloud)
    • Set a Dynamic Configuration Value (Self-Hosted)
    • Set the Time Zone
    • Share Dashboards
    • Shared Time Selector
    • Single Value Examples Gallery
    • Single Value Property Reference
    • Single Value Usage and Data Format
    • Single Value Widget
    • Step-by-Step Guide to Dashboards
    • Switch Kafka using KRaft Mode
    • Switching Kafka
    • Syslog via TLS Source
    • System tokens security policies (Self-Hosted)
    • Table Property Reference
    • Table Usage and Data Format
    • Table Widget
    • Table Widget Examples Gallery
    • Table Widget Interactions
    • Template Expressions
    • Template Variable Types
    • The humio Repository
    • The humio-activity repository
    • The humio-audit repository
    • The humio-fleet Repository
    • The humio-measurements Repository
    • The humio-metrics Repository
    • The humio-trigger-execution-info Repository
    • The humio-usage Repository
    • Thread Usage
    • Threat Type Distribution
    • Throttling for aggregate alerts
    • Throttling for legacy alerts
    • Time Chart Examples Gallery
    • Time Chart Property Reference
    • Time Chart Usage and Data Format
    • Time Chart Widget
    • Time Zone Settings
    • Time window for aggregate alerts
    • Time window for legacy alerts
    • Timestamp for aggregate alerts
    • Timestamp for legacy alerts
    • Trigger Management
    • Trigger Properties
    • Triggers
    • Understand Multi-Cluster Topologies (Self-Hosted)
    • Usage and Data Format
    • Using match() in Multi-Cluster Scenarios (Self-Hosted)
    • What Trigger Type to Choose
    • What's Measured (Cloud)
    • What's Measured (Self-Hosted)
    • Widget Gallery
    • Widget Time Selector
    • Widgets
    • Work with Dashboard Interactions
    • Work with Dashboard Parameters
    • Work with Time on Dashboards
    • World Map Examples Gallery
    • World Map Property Reference
    • World Map Usage and Data Format
    • World Map Widget
    • XSOAR Security Management
    • createIPFilter()
    • deleteIPFilter()
    • humio-organization-usage View
    • updateIPFilter()
  • Similar Content

    • Action Type: Webhooks
    • Creating an Alert, Actions section
    • Advanced Settings
    • Aggregate Alert Errors and Solutions
    • Apply Dashboard Filters
    • Automation
    • Built-in Parsers
    • Configuration Properties
    • Create Dashboards
    • Create Triggers
    • Create a Lookup File
    • Create a Scheduled PDF Role using the web interface
    • Cron Scheduling
    • Customize Dashboards
    • Dashboard Sections
    • Dashboards
    • Default Time Settings for Dashboards
    • Scheduled Search Properties
    • Delete a Repository or View
    • Design the Dashboard Layout
    • Disabling Access to Shared Dashboards
    • Edit Triggers
    • Errors when Using Live join() Functions
    • Export Dashboards as PDF
    • Filter Alert Errors and Solutions
    • Filter Match Highlighting
    • Frequent query operations
    • General Information About Triggers
    • Creating an Alert, General section
    • Ingest delay handling for aggregate alerts
    • Ingest delay handling for legacy alerts
    • Join Methods
    • Join Operation and Optimization
    • Legacy Alert Errors and Solutions
    • Live Dashboards
    • Lookup Files
    • Lookup Files Operations with match()
    • Make your Dashboard Interactive
    • Manage Dashboards
    • Manage Lookup Files
    • Manage Triggers
    • Managing Falcon LTR Repositories
    • Message Templates and Variables
    • Monitor Trigger Execution through the humio-activity Repository
    • Monitor, Diagnose, and Troubleshoot Triggers
    • Notifications
    • PDF Export Options
    • Query Debugging Functions
    • Query Joins and Lookups
    • Query Readability and Better Usage
    • Repository and View Settings
    • Restricting Access with IP Filters
    • Retry for aggregate alerts
    • Scheduled Report Operation and Limitations
    • Scheduled Reports Security
    • Scheduled Search Errors and Solutions
    • Section Time Selector
    • Send Events That Produced Aggregate Results to Actions
    • Set the Time Zone
    • Share Dashboards
    • Shared Time Selector
    • Step-by-Step Guide to Dashboards
    • Supported File Types and Formats
    • Template Expressions
    • Template Variable Types
    • Throttling for aggregate alerts
    • Throttling for legacy alerts
    • Time Zone Settings
    • Time window for aggregate alerts
    • Time window for legacy alerts
    • Timestamp for aggregate alerts
    • Timestamp for legacy alerts
    • Trigger Management
    • Trigger Properties
    • Triggers
    • Types of Join
    • Using Ad-hoc Tables
    • Using Lookup Files
    • Using the join() Function
    • Using the match() Function
    • Using the readFile() Function
    • Using the selfJoin() Function
    • What Trigger Type to Choose
    • Widget Time Selector
    • Work with Dashboard Interactions
    • Work with Dashboard Parameters
    • Work with Time on Dashboards
  • Related Language Syntax

    • Adding Fields to Events
    • Conditional Evaluation
    • Expressions
    • LogScale Regular Expression Engines
    • Operators
    • Persisted Aggregations Syntax
    • Query Filters
    • Regular Expression Flags
    • User Parameters (Variables)
    • Adding Fields to Events
    • Conditional Evaluation
    • Expressions
    • LogScale Regular Expression Engines
    • Operators
    • Persisted Aggregations Syntax
    • Query Filters
    • Regular Expression Flags
    • User Parameters (Variables)
  • Architecture

    • Ingestion: Digest Phase
  • Terminology

    • Alert
    • Cluster Management
    • Dashboard
    • LogScale Multi-Cluster Search (Self-Hosted)
    • Security
  • Related Guidance Articles

    • How-To: Dashboard Design Best Practices and Templates
    • How-To: Selecting Widgets Based on Query Output
    • How-To: Visualizing the Same Query With Different Widgets
    • Troubleshooting: IP Access for Actions or Notifiers
  • Related GraphQL API

    • createAggregateAlert()
    • createAlert()
    • createFilterAlert()
    • createIPFilter()
    • deleteAggregateAlertV2()
    • deleteAlert()
    • deleteFilterAlert()
    • deleteFilterAlertV2()
    • deleteIPFilter()
    • deleteLegacyAlert()
    • updateIPFilter()
  • Security (humio-audit) Events

    • Audit Log Event dashboard.delete
    • Audit Log Event dashboard.update
    • Audit Log Event readonly.dashboard.accessed
    • Audit Log Event readonly.dashboard.update
  • Training

    • Data Ingestion Overview
    • Log Sources
    • LogScale Product Tutorial with Demo Data
    • LogScale Video Series
    • Queries and Querying
    • Repositories

Enter search term